Provenance-Based Analytics Services for Access Control Policies

Provenance-Based Analytics Services for Access Control Policies
复制标题

基于来源的访问控制策略分析服务

DOI:
--
复制
发表时间:
2017
期刊:
World Congress on Services
影响因子:
--
通讯作者:
Christopher Williams
Christopher Williams
中科院分区:
--
文献类型:
--
作者:
E. Bertino;A. A. Jabal;S. Calo;C. Makaya;Maroun Touma;D. Verma;Christopher Williams

文献摘要

被引文献

相似文献

成功的协作需要信息和资源共享,因此需要适当的访问控制策略管理系统来控制协作实体之间的共享。这样的管理系统需要是灵活的,以适应不同的环境,从而能够支持访问控制策略的演变。然而,在处理大量不断演变的政策时,政策必须符合某些“政策质量要求”。具体而言,相关政策必须是最新的、完整的、没有不一致的、相关的。在本文中,我们提出了一种方法来分析政策,以确定政策是否符合这些要求。我们的方法是基于使用的出处技术,收集全面的数据,由用户在工作流的上下文中执行的动作,即,根据用户的一些排序执行的任务集。支持各种类型分析的服务使用起源数据来确定感兴趣的策略是否验证了质量要求。
Successful collaborations require information and resource sharing and thus adequate access control policy management systems that control sharing among the collaborating entities. Such management systems need to be flexible in order to adapt to different environments and thus be able to support access control policy evolution. However, when dealing with large sets of evolving policies it is critical that policies meet certain "policy quality requirements". Specifically, policies of interest must be up-to-date, complete, free of inconsistencies, relevant. In this paper, we propose an approach to analyze policies in order to determine whether policies meet such requirements. Our approach is based on the use of provenance techniques that collect comprehensive data about actions executed by users in the context of workflows, that is, sets of tasks executed according to some ordering by users. Provenance data are used by services that support various types of analysis to determine whether the policies of interest verify the quality requirements.